US12609817B2UtilityA1

Systems and methods for a quantum safe certificate ledger

Priority: Filed: Jan 9, 2024Granted: Apr 21, 2026
H04L 63/0861H04L 9/3247H04L 9/0852
28
PatentIndex Score
0
Cited by
20
References
20
Claims

Abstract

A quantum safe blockchain system can operate with quantum safe blockchain nodes (QSBN) and validators. A QSBN can generate a pending register certificate transaction comprising a public key, a fingerprint for a certificate, a URL for the certificate, a first registration number for a parent certificate of the certificate, and a digital signature. The QSBN can transmit the pending register certificate transaction to the quantum safe blockchain system. A validator can receive the pending transaction, validate the digital signature using the public key and include a confirmed register certificate transaction in a block. The confirmed transaction can include a second registration number for the certificate. The QSBN can receive the confirmed transaction and store in a database the fingerprint, the first registration number, and the second registration number. The QSBN can generate a pending certificate revocation transaction for the certificate, and transmit the pending transaction to the blockchain system.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
         1 . A method for a quantum safe blockchain node to generate a pending register certificate transaction, the method performed by the quantum safe blockchain node (QSBN), the method comprising:
 a) storing in a nonvolatile memory (i) a post-quantum cryptography (PQC) digital signature algorithm, (ii) a private key and corresponding public key for the PQC digital signature algorithm, (iii) a one-time signature (OTS) index value associated with the public key, and (iv) a contract address for a register certificate transaction;   b) receiving, via a network interface, a uniform resource locator (URL) for a certificate, an address for an owner of the certificate, a first registration number for a parent certificate of the certificate, and at least one of a fingerprint for the certificate and the certificate;   c) storing, in a RAM memory, data for a pending register certificate transaction comprising the public key, a transaction nonce comprising the OTS index value, a transaction amount, the address for the owner, the fingerprint for the certificate, the URL, the first registration number, and an expiration time for the certificate;   d) generating, by a processor, a PQC digital signature using the PQC digital signature algorithm, the private key, and the OTS index value, the PQC digital signature over at least the data for the pending register certificate transaction;   e) transmitting, by the network interface, to a blockchain network the data for the pending register certificate transaction and the digital signature and receiving a confirmed register certificate transaction for a block, the data, the digital signature, and a second registration number for the certificate; and   f) storing, from the confirmed register certificate transaction, at least the fingerprint for the certificate, the first registration number for the parent certificate, and the second registration number for the certificate.   
     
     
         2 . The method of  claim 1 , wherein the PQC digital signature algorithm comprises the e Xtended Merkle Signature Scheme (XMSS) or the Leighton-Micali Signature (LMS) algorithm. 
     
     
         3 . The method of  claim 1 , wherein the PQC digital signature algorithm comprises the CRYSTALS-Dilithium algorithm. 
     
     
         4 . The method of  claim 1 , wherein the fingerprint for the certificate is computed using a secure hash function comprising SHA-2, SHA-3, or SHAKE256. 
     
     
         5 . The method of  claim 1 , wherein the QSBN verifies that the fingerprint is not already present in a local ledger or database prior to transmitting the pending register certificate transaction. 
     
     
         6 . The method of  claim 1 , wherein the address for the owner of the certificate is a quantum safe public key corresponding to a stateless signature algorithm. 
     
     
         7 . The method of  claim 1 , further comprising:
 prior to transmitting the pending register certificate transaction, verifying that the transaction amount meets or exceeds a required minimum token value associated with the contract address.   
     
     
         8 . The method of  claim 1 , wherein the contract address is associated with a quantum safe smart contract deployed on a blockchain virtual machine supporting post-quantum cryptographic execution. 
     
     
         9 . The method of  claim 1 , wherein the transaction nonce is selected to be equal to the OTS index value used in generating the digital signature. 
     
     
         10 . The method of  claim 1 , wherein the confirmed register certificate transaction is stored in a relational SQL database linked to the QSBN. 
     
     
         11 . The method of  claim 1 , further comprising:
 generating the fingerprint for the certificate by computing a hash of the DER-encoded representation of the certificate.   
     
     
         12 . The method of  claim 1 , wherein the certificate is an X.509 version 3 certificate. 
     
     
         13 . The method of  claim 1 , further comprising:
 storing a record associating the second registration number with a block number and a transaction index within the block.   
     
     
         14 . The method of  claim 1 , wherein the QSBN is configured to receive the certificate from the URL and independently verify that its hash matches the received fingerprint. 
     
     
         15 . The method of  claim 1 , further comprising:
 g) generating, by the processor, a pending certificate revocation transaction comprising the fingerprint for the certificate and a revocation reason code.   
     
     
         16 . The method of  claim 15 , wherein the pending certificate revocation transaction further comprises the address for the owner of the certificate and the second registration number for the certificate. 
     
     
         17 . The method of  claim 15 , further comprising:
 h) generating, by the processor, a second PQC digital signature over the revocation transaction using the private key and an incremented OTS index value.   
     
     
         18 . The method of  claim 17 , wherein the revocation transaction is transmitted to a smart contract address associated with a quantum safe revocation contract on the blockchain. 
     
     
         19 . The method of  claim 15 , wherein the revocation transaction is stored in a block along with a timestamp and transaction identifier, and the QSBN stores the revocation status in a local database. 
     
     
         20 . The method of  claim 15 , further comprising:
 retrieving the confirmed revocation transaction from the blockchain and verifying the stored revocation status prior to responding to queries regarding the certificate.

Join the waitlist — get patent alerts

Track US12609817B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.